9 ms·
It’s hilarious that the first "vulnerability" in the example report[0] linked in this page is basically "SSH is accessible". Well… Duh ! [0] https://www.rsync.
by navaati 6y ago
It’s hilarious that the first "vulnerability" in the example report[0] linked in this page is basically "SSH is accessible". Well… Duh !
[0] https://www.rsync.net/resources/regulatory/PCI_usw-s005_report.pdf https://www.rsync.net/resources/regulatory/PCI_usw-s005_repo...
EDIT: It’s marked as "PASS" though, so it’s all fine, just funny.
- vidarh 6y agoI once had a someone report responding to ping as a vulnerability. For the public facing firewall. We sent them back a link of prominent servers that respond to ping. Including the web server of the expensive agency that had produced the report. And whose web server had an expired SSL certificate.
- Alupis 6y agoWell, PCI compliance is different from regular server administration (a lot of it being smoke and mirrors, yes). I do not believe ICMP (ping) is an automatic-fail condition for PCI (at least for certain SAQ levels that I'm familiar with) - however they do show up as warnings, particularly if you can get a timestamp response (to be used in timing-based attacks). PCI prefers systems that handle CHD be "invisible" to the outside world, in an attempt to hide the systems an attacker might take interest in. Not always feasible (eCommerce, for example), but you gotta jump through the PCI hoops if you don't want to be stuck holding the bag if there's some breach.
- darkarmani 6y agoPCI compliance is to reduce the chances of legal liability. Better security is sometimes a side-effect of that compliance.
- humaniania 6y agoTo reduce the liability of the credit card company maybe, by making the process so complex and onerous that it is virtually impossible to complete a survey without some error or omission that would almost assuredly be used as a reason to invalidate any liability for the credit card company should some bad event take place. Source: have had to complete PCI surveys from multiple vendors.
- vidarh 6y agoThis was not for PCI compliance. And the system by definition could not be invisible - the ip in question was in DNS and was what you'd connect to the web servers on.
- technothrasher 6y agoI used to get so tired of having to write up explanations of why my FreeBSD server couldn't possibly have failed a security check for a Linux vulnerability, or that the web server they were complaining about didn't actually exist, or a million other retarded false positives every quarter. Thank goodness I don't deal with PCI any longer.
- vidarh 6y agoFor the last security report I had to deal with for a client, the main vulnerabilities were reported against a Google site that was merely linked to from the clients site. Not PCI compliance, so more flexibility in dealing with their incompetence, thankfully. They reported a number of purported (non-existing) "vulnerabilities" against said Google site that included that it stopped responding to their probing soon after they started hammering it with sketchy requests... They did, to be fair, point out that this could be a defence mechanism, but dinged it for preventing them from checking for other vulnerabilities. At least I didn't have to explain why that one was nonsense - it was rather obvious to my client that the agency they'd hired were being idiots. It's not like it was difficult to see either - the domain name of the site they'd hit had "google" in it.
- Alupis 6y agoSounds like a scan mis-configuration on your client's part. All PCI vuln scanners I've used require you to specify IP addresses and Domain Names you want scanned, and do not follow on-page external links.
- vidarh 6y agoNot the client. Third party agency hired to assess the security, and who clearly did not apply any critical thinking before sending it off. And as I pointed out, not PCI.
- greatquux 6y agotenable keeps telling me that something "interfered" with its scans for PCI compliance - isn't the point of a firewall IPS system to do that? but i don't even have it on for the IP in question, so I basically have to just edit my network range to remove it. it really is bullshit.
- raverbashing 6y agoTalking about PCI compliance I always remember this: https://serverfault.com/questions/293217/our-security-auditor-is-an-idiot-how-do-i-give-him-the-information-he-wants https://serverfault.com/questions/293217/our-security-audito...
- navaati 6y agoOh wow this is next level though.
- croutonwagon 6y agoMy parent org is starting to take their vuln scan results and report them to c levels. When they told me I informed them I stopped using their vulnerability scanner years ago because they would not allow me to chnage anything in it, including exclusions to icmp time stamps or other vulns Ive mitigated while proper fixes were in the works. So I rolled my own and use that to audit my systems. They don’t care because “policy”. My c levels will just ask and then promptly disregard all future reports, adding to the noise
- technion 6y agoI did a job where I was given access to a server in the form of a set of credentials for an HPE iLO, which was accessible over the Internet. From there, we could use the remote console to logon as root. HPE iLO doesn't support MFA or any form of public key authentication, and its security history is much worse than SSH. It requires several ports open and the old version they had required Java plugins on desktops and all sorts of nonsense. Using it outside of emergency repairs is a terrible experience due to console refresh lag and the fact you can't copy + paste. The reason I had to do this insecure and annoying process is that a PCI assessor had told them it would be a hard fail to have port 22 open on the Internet, but this would apparently be fine.
- function_seven 6y agoI don't know... I mean, maybe the security posture is to annoy the hackers into giving up? ("This thing requires a Java applet and is slow as hell. Screw it, let's just pwn the bank across the street") I'll call it Security by Inconvenience.
- catmanjan 6y agoThat's why your security solution should include a mix of every known technology, hackers need to know everything from COBOL to rust
- tjalfi 6y agoThat reminds me of a post[0] on alt.sysadmin.recovery. The hackers were annoyed by the compromised machine so they installed security updates and did other system administration tasks. [0] https://groups.google.com/g/alt.sysadmin.recovery/c/ITd7OlMr21g/m/e0OU5zqYvRgJ https://groups.google.com/g/alt.sysadmin.recovery/c/ITd7OlMr...
- krylon 6y agoI vaguely recall some kind of malware that upon infecting a system scanned the system for other malware and removed/disabled it. The motives were far from pure, obviously. (Although there also was a case, I think, of a piece of malware specifically created to ensure "infected" system had up to date AV software and were up to date update-wise. We sure live in strange times.)
- a012 6y agoIt irks me a lot that GCP always put "SSH port opens" in Security Command Center as HIGH Vuln. while I'm running private subnets, FFS.